Digital Forensics Analysts

Computer and Mathematical Occupations
O*NET-SOC code
15-1299.06

Conduct investigations on computer-based crimes establishing documentary or physical evidence, such as digital media and logs associated with cyber intrusion incidents. Analyze digital evidence and investigate computer security incidents to derive information in support of system and network vulnerability mitigation. Preserve and present computer-related evidence in support of criminal, fraud, counterintelligence, or law enforcement investigations.

AI exposure

  • Data source: BLSPublished: 2026-08

    Very high· relative

    LowFour relative bandsVery high

    Group-level value

    Scale, basis and source

    Four relative bands (Low / Moderate / High / Very high)

    831 detailed occupations in the BLS Employment Projections table. Assigned per National Employment Matrix (NEM) code, so occupations sharing a NEM code carry the same band

    Source dataset (XLSX download)

  • Data source: AnthropicPublished: 2026-03

    0.311

    0.000Range of values carried here0.745

    Group-level value

    Scale, basis and source

    Observed exposure index, 0–1 as published

    Mapped onto O*NET tasks

    Published per SOC 2018 occupation; every O*NET occupation with the same SOC 2018 code carries this value

    Source dataset (CSV download)

  • Data source: ILOPublished: 2025

    0.43–0.55· 3 ISCO-08 groups

    Scale, basis and source

    Generative AI exposure index, 0–1 as published

    Published per ISCO-08 unit group. Linked to this occupation, wholly or in part, by applying U.S. Bureau of Labor Statistics crosswalks (ISCO-08 to 2010 SOC, 2010 SOC to 2018 SOC) as published

    Source dataset (PDF download)

What kind of figure this source publishes

The BLS category is a relative rank, not an absolute level, and it is not a first-hand measurement: it groups an occupation's percentile ranks across several published studies into four bands. It is not an employment or wage forecast, not a probability of adoption, and it does not separate automation from augmentation.

ILO value for each linked ISCO-08 group
  • ISCO-08 2519Software and Applications Developers and Analysts Not Elsewhere Classified0.55
  • ISCO-08 2529Database and Network Professionals Not Elsewhere Classified0.49
  • ISCO-08 3511Information and Communications Technology Operations Technicians0.43

AI exposure (OpenAI rubric)

20 rated tasks · 20 tasks with β ≥ 0.5 (100.0%)

β = direct exposure (E1) + 0.5 × exposure when tools are available (E2), per the source repository's definition.

  • Source unit: O*NET 27.2 tasks → O*NET 31.0 occupation code
  • All rated tasks are in the O*NET 31.0 task list.
Source
OpenAI "GPTs are GPTs" exposure rubric
Release
gh-main-0471612
License
MIT License, Copyright (c) 2024 OpenAI

Tasks

Task statements from the O*NET® 31.0 Database, core tasks first.

TaskTypeβ (OpenAI)
Adhere to legal policies and procedures related to handling digital media.Core1
Analyze log files or other digital information to identify the perpetrators of network intrusions.Core0.5
Create system images or capture network settings from information technology environments to preserve as evidence.Core0.5
Develop plans for investigating alleged computer crimes, violations, or suspicious activity.Core0.5
Develop policies or requirements for data collection, processing, or reporting.Core0.5
Duplicate digital evidence to use for data recovery and analysis procedures.Core1
Identify or develop reverse-engineering tools to improve system capabilities or detect vulnerabilities.Core1
Maintain cyber defense software or hardware to support responses to cyber incidents.Core1
Maintain knowledge of laws, regulations, policies or other issuances pertaining to digital forensics or information privacy.Core0.5
Perform file signature analysis to verify files on storage media or discover potential hidden files.Core0.5
Perform forensic investigations of operating or file systems.Core0.5
Perform web service network traffic analysis or waveform analysis to detect anomalies, such as unusual events or trends.Core0.5
Preserve and maintain digital forensic evidence for analysis.Core0.5
Recover data or decrypt seized data.Core1
Write cyber defense recommendations, reports, or white papers using research or experience.Core1
Write reports, sign affidavits, or give depositions for legal proceedings.Core1
Write technical summaries to report findings.Core1
Conduct predictive or reactive analyses on security measures to support cyber security initiatives.Supplemental0.5
Recommend cyber defense software or hardware to support responses to cyber incidents.Supplemental0.5
Write and execute scripts to automate tasks, such as parsing large data files.Supplemental1

Occupation information

Sources and attribution

This page includes information from the O*NET® 31.0 Database (https://www.onetcenter.org/database.html) by the U.S. Department of Labor, Employment and Training Administration (USDOL/ETA). Used under the CC BY 4.0 license (https://creativecommons.org/licenses/by/4.0/). O*NET® is a trademark of USDOL/ETA. AI Changing Work has modified all or some of this information: the O*NET-SOC code, title and task statements are reproduced in English without change; task-type labels are shown in the page's language and tasks are listed core first; any Korean occupation title shown on the Korean-language page is AI Changing Work's translation; any KSCO-8 unit groups linked to this occupation were paired with it by AI Changing Work's judgment, and the relation labels and statuses are AI Changing Work's additions. USDOL/ETA has not approved, endorsed, or tested these modifications.

Any AI exposure figures on this page are published by third parties, not by AI Changing Work, and none is part of the O*NET information. OpenAI publishes task-level scores (MIT License) for O*NET 27.2 task statements; each is shown next to the O*NET 31.0 task statement with the same task ID, whose wording can differ from the 27.2 statement that was scored. OpenAI also publishes occupation-level scores for O*NET-SOC codes in the same release, and any such score is shown on the O*NET occupation with the same code. Anthropic publishes an observed exposure index in the Anthropic Economic Index (CC-BY), and the U.S. Bureau of Labor Statistics publishes relative AI exposure categories (public domain); both are published per SOC code, and each value is shown on every O*NET occupation with that code. The International Labour Organization publishes a generative AI exposure index in ILO Working Paper 140 (CC BY 4.0) for ISCO-08 unit groups; AI Changing Work links those groups to O*NET occupations by applying the U.S. Bureau of Labor Statistics ISCO-08 to 2010 SOC and 2010 SOC to 2018 SOC crosswalks as published, without case-by-case selection, and these crosswalks match many groups only in part. Where several unit groups are linked, each group's published value is listed, and any summary shows only the lowest and highest of those values with the number of groups; no exposure figure is averaged or recalculated. Any employment figures are published by the U.S. Bureau of Labor Statistics for the SOC group containing this occupation. Each source is credited where its figures are shown.

O*NET OnLine: 15-1299.06 Digital Forensics Analysts

KSCO 코드·명칭: 한국표준직업분류(제8차 개정) — 통계청 고시 제2024-328호 (2024-07-01 고시, 2025-01-01 시행). 저작권법 제7조 제2호의 고시 항목이다. 명칭 표기(가운뎃점·띄어쓰기)는 해설서 2차 정오 반영판의 표기를 따랐으며, 고시 항목표와는 18개 명칭에서 가운뎃점 글리프나 띄어쓰기만 다르다. 통계청은 2025년 10월 국가데이터처로 개편되었다. 이 페이지의 KSCO 연결은 통계청·국가데이터처의 공식 연계표가 아니다.

Full attribution and licenses